# Key Management Services Upgrade

> Moved a client's KMS activation host off end-of-support Windows Server 2012 onto 2022, right after the PKI upgrade.

Canonical: https://mikereams.com/work/key-management-services-upgrade

Year: 2023  
Change: WS2012 → WS2022  
Technology: Active Directory  
Topics: KMS, PKI, Volume License, Windows, Security, Cyber Security, IT Governance, Cryptography, Governance, Risk, and Compliance, Identity and Access Management, Certificate Authority, Information Security, Private Key Infrastructure  
Write-ups: [Moving a KMS Host From Windows Server 2012 to 2022](https://mikereams.com/writing/key-management-services-2012-upgrade)

![Key Management Services Upgrade](https://mikereams.com/work/7f4c3f8d1fea7c769a0f9e4418d4f2f05d6fcd90-850x490.png)

## The situation

After we [upgraded the client's internal PKI](https://mikereams.com/work/windows-2012-pki-upgrade-to-2022), their Key Management Service host — which activates volume-licensed Windows and Office across the network — was still on Windows Server 2012, heading for end of support in October 2023.

## What I did

- Retired the 2012 host: removed its host key and its DNS SRV record.
- Stood up the Windows Server 2022 host and activated it with Microsoft.
- Verified that clients found the new host through DNS and that its activation count climbed.

The full procedure, with commands: [Moving a KMS Host From Windows Server 2012 to 2022](https://mikereams.com/writing/key-management-services-2012-upgrade).
